Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

TON Price Prediction: $1.50 Target as Technical Indicators Signal Potential 13% Rally

May 2, 2026

The Cheap Foreign Labor Regime Blocking Agricultural Intelligence

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»New macOS Malware Targets Cracked Apps
New macOS Malware Targets Cracked Apps
Security

New macOS Malware Targets Cracked Apps

March 14, 2026No Comments2 Mins Read

Security researchers have discovered a new and previously unknown macOS malware that exploits pirated software to infiltrate users’ systems.

The malware, distinct from unauthorized proxy server installations, proved highly sophisticated in its approach, according to a new advisory by Kaspersky.

Repackaging pre-cracked applications as PKG files, malicious actors embedded a Trojan proxy and a post-install script within apps circulating on pirating websites. This malware, targeting macOS Ventura 13.6 and newer versions, operated on both Intel processors and Apple silicon machines.

Named “Activator.app,” the malware displayed a seemingly unsophisticated GUI with a PATCH button. However, a closer inspection revealed a Python 3.9.6 installer and an extra Mach-O file named “tool” within the Resources folder. Activator utilized an obsolete function, AuthorizationExecuteWithPrivileges, to gain administrator privileges. This ultimately enabled the execution of a Python script that patched the downloaded app.

The malware’s second stage involved reaching out to a command-and-control (C2) server by making a DNS request for a TXT record containing an encrypted script. The decrypted script, executed by a tool, displayed capabilities such as killing NotificationCenter processes and installing launch agents for persistent execution.

Stage three of the malware revealed a backdoor that communicated with the C2 server, sending information about the infected system, installed applications and more. Kaspersky clarified that while the server did not issue commands during the investigation, it hinted at the ongoing development of the malware campaign.

Finally, stage four of the malware unveiled a crypto-stealing component, replacing legitimate cryptocurrency wallets with infected versions. The malware operators embedded malicious code in applications like Exodus and Bitcoin-Qt to steal users’ wallet information.

Read more on macOS malware: Potent Trojans Targeting MacOS Users

According to Sergey Puzan, a security researcher at Kaspersky, this discovery emphasizes the susceptibility of users who use cracked applications.

See also  North Korean Hackers Target macOS Crypto Engineers With Kandykorn

“Cybercriminals use pirated apps to easily access users’ computers and get admin privileges by asking them to enter the password. The creators show unusual creativity by hiding a Python script in a DNS server’s record, increasing malware’s level of stealth in the network’s traffic.”

To safeguard against this potential threat, users should exercise heightened vigilance, particularly regarding their cryptocurrency wallets, refrain from downloading content from dubious websites and opt for reliable cybersecurity solutions to enhance overall protection.

Source link

Apps Cracked macOS Malware Targets

Related Posts

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

Satacom Malware Campaign Steals Crypto Via Stealthy Browser Extension

October 1, 2023

Sam Altman ‘Excited’ About Bitcoin, Worries About CBDCs

October 9, 2023

XRP DeFi opens to institutions as Hex Trust adds custodial FXRP access

February 6, 2026

Type above and press Enter to search. Press Esc to cancel.